<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T10:13:02.315760+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2024:4351</id>
    <title>ALSA-2024:4351 — Low: virt:rhel and virt-devel:rhel security and bug fix update</title>
    <updated>2026-10-03T10:13:02.611300+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: SLOF, AlmaLinux:8: hivex, AlmaLinux:8: hivex-devel, AlmaLinux:8: libguestfs, AlmaLinux:8: libguestfs-appliance, AlmaLinux:8: libguestfs-bash-completion, AlmaLinux:8: libguestfs-devel, AlmaLinux:8: libguestfs-gfs2, AlmaLinux:8: libguestfs-gobject, AlmaLinux:8: libguestfs-gobject-devel and 120 more</p>
<p>Kernel-based Virtual Machine (KVM) offers a full virtualization solution for Linux on numerous hardware platforms. The virt:rhel module contains packages which provide user-space components used to run virtual machines using KVM. The packages also provide APIs for managing and interacting with the virtualized systems.</p>
<p>Security Fix:</p>
<p>* virt:rhel/libvirt: stack use-after-free in virNetClientIOEventLoop (CVE-2024-4418)</p>
<p>Bug fix:</p>
<p>* virsh destroy with --graceful destroyed a paused guest (qemu process paused by SIGSTOP) (JIRA:AlmaLinux-36064)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2024:4351"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-04436</id>
    <title>bdu:2024-04436</title>
    <updated>2026-10-03T10:13:02.611505+00:00</updated>
    <content>bdu:2024-04436</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-04436"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2024-4418</id>
    <title>BELL-CVE-2024-4418</title>
    <updated>2026-10-03T10:13:02.611525+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:stream: libvirt</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2024-4418"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-270736</id>
    <title>EUVD-2026-270736</title>
    <updated>2026-10-03T10:13:02.611544+00:00</updated>
    <content>EUVD-2026-270736</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-270736"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-4418</id>
    <title>fkie_cve-2024-4418</title>
    <updated>2026-10-03T10:13:02.611556+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A race condition leading to a stack use-after-free flaw was found in libvirt. Due to a bad assumption in the virNetClientIOEventLoop() method, the `data` pointer to a stack-allocated virNetClientIOEventData structure ended up being used in the virNetClientIOEventFD callback while the data pointer's stack frame was concurrently being "freed" when returning from virNetClientIOEventLoop(). The 'virtproxyd' daemon can be used to trigger requests. If libvirt is configured with fine-grained access control, this issue, in theory, allows a user to escape their otherwise limited access. This flaw allows a local, unprivileged user to access virtproxyd without authenticating. Remote users would need to authenticate before they could access it.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-4418"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-q262-3hfr-f5q4</id>
    <title>GHSA-q262-3hfr-f5q4</title>
    <updated>2026-10-03T10:13:02.611582+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A race condition leading to a stack use-after-free flaw was found in libvirt. Due to a bad assumption in the virNetClientIOEventLoop() method, the `data` pointer to a stack-allocated virNetClientIOEventData structure ended up being used in the virNetClientIOEventFD callback while the data pointer's stack frame was concurrently being "freed" when returning from virNetClientIOEventLoop(). The 'virtproxyd' daemon can be used to trigger requests. If libvirt is configured with fine-grained access control, this issue, in theory, allows a user to escape their otherwise limited access. This flaw allows a local, unprivileged user to access virtproxyd without authenticating. Remote users would need to authenticate before they could access it.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-q262-3hfr-f5q4"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2024-4418</id>
    <title>msrc_CVE-2024-4418 — Libvirt: stack use-after-free in virnetclientioeventloop()</title>
    <updated>2026-10-03T10:13:02.611601+00:00</updated>
    <content>msrc_CVE-2024-4418</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2024-4418"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2024-1683</id>
    <title>OESA-2024-1683 — libvirt security update</title>
    <updated>2026-10-03T10:13:02.611619+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: libvirt, openEuler:20.03-LTS-SP4: libvirt, openEuler:22.03-LTS: libvirt, openEuler:22.03-LTS-SP1: libvirt, openEuler:22.03-LTS-SP2: libvirt, openEuler:22.03-LTS-SP3: libvirt</p>
<p>Libvirt is a C toolkit to interact with the virtualization capabilities of recent versions of Linux (and other OSes). The main package includes the libvirtd server exporting the virtualization support.

Security Fix(es):

A race condition leading to a stack use-after-free flaw was found in libvirt. Due to a bad assumption in the virNetClientIOEventLoop() method, the `data` pointer to a stack-allocated virNetClientIOEventData structure ended up being used in the virNetClientIOEventFD callback while the data pointer&amp;apos;s stack frame was concurrently being &amp;quot;freed&amp;quot; when returning from virNetClientIOEventLoop(). The &amp;apos;virtproxyd&amp;apos; daemon can be used to trigger requests. If libvirt is configured with fine-grained access control, this issue, in theory, allows a user to escape their otherwise limited access. This flaw allows a local, unprivileged user to access virtproxyd without authenticating. Remote users would need to authenticate before they could access it.(CVE-2024-4418)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2024-1683"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13948-1</id>
    <title>openSUSE-SU-2024:13948-1 — libvirt-10.3.0-2.1 on GA media</title>
    <updated>2026-10-03T10:13:02.611655+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libvirt-10.3.0-2.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:13948-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2024:4351</id>
    <title>RHSA-2024:4351 — Red Hat Security Advisory: virt:rhel and virt-devel:rhel security and bug fix update</title>
    <updated>2026-10-03T10:13:02.611672+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libvirt: stack use-after-free in virNetClientIOEventLoop()</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2024:4351"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2024:1962-1</id>
    <title>SUSE-SU-2024:1962-1 — Security update for libvirt</title>
    <updated>2026-10-03T10:13:02.611688+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for libvirt</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2024:1962-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-4418</id>
    <title>UBUNTU-CVE-2024-4418</title>
    <updated>2026-10-03T10:13:02.611702+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:24.04:LTS: libvirt</p>
<p>A race condition leading to a stack use-after-free flaw was found in libvirt. Due to a bad assumption in the virNetClientIOEventLoop() method, the `data` pointer to a stack-allocated virNetClientIOEventData structure ended up being used in the virNetClientIOEventFD callback while the data pointer's stack frame was concurrently being "freed" when returning from virNetClientIOEventLoop(). The 'virtproxyd' daemon can be used to trigger requests. If libvirt is configured with fine-grained access control, this issue, in theory, allows a user to escape their otherwise limited access. This flaw allows a local, unprivileged user to access virtproxyd without authenticating. Remote users would need to authenticate before they could access it.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-4418"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1017</id>
    <title>WID-SEC-W-2024-1017 — Red Hat Enterprise Linux (libvirt): Schwachstelle ermöglicht Denial of Service</title>
    <updated>2026-10-03T10:13:02.611724+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1017"/>
  </entry>
</feed>
